OpenSSF/OSV advisory MAL-2026-16181 confirms this npm version as malicious. The package's postinstall lifecycle script runs a bash reverse shell that opens a TCP connection to the hardcoded host 14.225.210.85 on port 443 and binds an interactive shell to that socket, granting whoever operates that endpoint full interactive command execution on the installer's host. Execution is automatic on `npm install` via scripts.postinstall, requires no user action, and also writes a marker file under...
This report applies to strapi-plugin-plsresh-meeb@3.6.8.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
This report uses published external intelligence. The advisory does not provide a separate source-code analysis for each listed version.